IP Intelligence Briefing: 183.6.115.88
Date: 2026-06-17
---
**1. Core Profile**
- Risk Score: 80 (High Risk)
- Ownership:
- ISP: China Telecom (ASN 4134)
- Network: CHINANET-GD (APNIC)
- Location: Guangdong, China (Geolocation inferred with 2500km accuracy radius).
- Threat Indicators:
- 6 DNSBL listings (high-severity).
- No direct malware, phishing, or exploit indicators.
- No known attacker/campaign associations.
---
**2. Observation History**
- Recent Activity (Last 30 Days):
- DNSBL Listings: Detected on 2026-06-17 (80% confidence).
- Network Stability: No persistent malicious behavior; threat observation count = 1.
- Geolocation Consensus: Plausible (inferred via multiple sources).
---
**3. Relationships**
- Network Affiliations:
- Linked to CHINANET-GD (same network as 32+ other IPs).
- No direct ties to known malicious organizations, domains, or certificates.
- Services:
- No open ports, TLS certs, or HTTP services detected.
---
**4. Neighborhood Analysis**
- Subnet: 183.6.115.88/24
- Abuse Density: 0% (no active neighbors identified; subnet classified as "mostly clean").
- Isolation: This IP appears isolated within its subnet, with no neighboring IPs flagged for abuse.
---
**5. Key Findings & Recommendations**
- Primary Risk: High risk score driven by 6 DNSBL listings (e.g., Spamhaus, OpenBL) despite no direct malicious activity.
- Action Required:
- Monitor DNS-related traffic (e.g., domain resolution, email headers).
- Consider blocking the IP due to high risk, especially if itβs associated with spam or phishing campaigns.
- Verify DNSBL listings with upstream providers (China Telecom).
- Context: While the subnet is otherwise clean, the IPβs high risk score suggests potential misuse (e.g., spoofing, botnet activity).
---
Note: No firewall rules or security actions recommended due to lack of confirmed malicious activity, but vigilance is advised.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | IPMASTER CHINANET-GD |
| ASN | AS4134 |
| Network Name | β |
| CIDR Block | β |
| RIR | APNIC |
| Country | β |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR Record | No PTR |
| Forward Confirmed | No β PTR hostname does not resolve back to this IP (weak signal) |
π DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Mobile |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 26% | 2 | 3 |
| routing | 13% | 1 | 1 |
| services | 11% | 1 | 2 |
| ownership | 26% | 2 | 3 |
| reputation | 21% | 1 | 3 |
| geolocation | 21% | 2 | 2 |
| Overall | 20% | 9 | 14 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-05-07 23:04:00 UTC |
| Last Seen | 2026-06-26 18:10:53 UTC |
| Profile Built | 2026-06-23 00:30:23 UTC |
| Data Freshness | Live |
| Signal Types | 21 |
| Total Observations | 23 |
Full dossier details are available via our API.